๐Ÿ” CVE Alert

CVE-2026-19359

MEDIUM 4.7

nxp-auto-goldvip gvip Lambda Function SitewiseCustomFunction access control

CVSS Score
4.7
EPSS Score
0.0%
EPSS Percentile
0th

A security vulnerability has been detected in nxp-auto-goldvip gvip up to 1.4.0. Affected by this issue is the function SitewiseCustomFunction of the component Lambda Function Handler. Such manipulation leads to improper access controls. The attack can be launched remotely. Upgrading to version 1.15.0 can resolve this issue. Upgrading the affected component is advised. The project explains: "The reported IAM permission configuration is a known historical issue that was already addressed in 2024, beginning with GoldVIP version 1.13.0. The permissions were updated in subsequent releases, including version 1.15.0. In addition, we also sent a request to either update or deprecate the older release in the AWS SAR application repository."

CWE CWE-284 CWE-266
Vendor nxp-auto-goldvip
Product gvip
Published Aug 9, 2026
Stay Ahead of the Next One

Get instant alerts for nxp-auto-goldvip gvip

Be the first to know when new medium vulnerabilities affecting nxp-auto-goldvip gvip are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L/E:X/RL:O/RC:C
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

nxp-auto-goldvip / gvip
1.0 1.1 1.2 1.3 1.4.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
vuldb.com: https://vuldb.com/vuln/387213 vuldb.com: https://vuldb.com/vuln/387213/cti vuldb.com: https://vuldb.com/cve/CVE-2026-19359 vuldb.com: https://vuldb.com/submit/866022 github.com: https://github.com/nxp-auto-goldvip/gvip/releases/tag/goldvip-1.15.0

Credits

๐Ÿ” changli (VulDB User) VulDB CNA Team